Cybersecurity Consultant - Policies and Standards
- Pay Rate: $64.03 /hour, depending on experience
-
Contract Length: 6 Months
Location: Vancouver, British Columbia
-
Raise is currently hiring a Cybersecurity Consultant - Policies and Standards on behalf of our client. They’re expanding their team to meet growing needs, making this a unique opportunity to work with an industry leader. Our Client, is one of the largest electrical energy suppliers in Canada.
Note: The primary pay rate is based on T4 classification; however, we will also consider applications from candidates interested in an INC classification, where applicable.
Description
The Cybersecurity Consultant – Policies and Standards to join the cybersecurity governance team. Reporting to the Cybersecurity Governance and Performance Lead, this role plays a pivotal part in protecting our clients critical information infrastructure by reviewing, developing, and refining cybersecurity policies and standards.
The ideal candidate brings a strong background in policy development paired with a deep understanding of cybersecurity risks, enterprise IT environments, and Operational Technology (OT) systems. Working collaboratively with internal stakeholders across the organization, you will act as a trusted advisor to address concerns, identify control gaps, and tailor a robust framework of policies and standards that align with industry best practices and regulatory compliance.
Responsibilities
-
Policy Development & Review: Lead the development, tuning, and maintenance of ’s cybersecurity policies, standards, and guidelines. Work collaboratively with stakeholders to address issues, incorporate operational feedback, and ensure smooth implementation.
-
Gap Analysis & Recommendations: Identify control gaps regarding existing policies and standards, conducting thorough evaluations to recommend prioritized actions tailored to ’s unique IT and OT environments.
-
Governance & Framework Alignment: Apply deep knowledge of recognized standards and frameworks—including NIST CSF, NIST 800-53r5, RMF, AI RMF, ISO 27001/2, COBIT, cloud security, and emerging AI risks.
-
Risk Mitigation & Compliance Support: Assist in reducing and mitigating security risks to ensure compliance with digital technology regulations, including North American Electric Reliability Corporation Critical Infrastructure Protection (NERC CIP) and BC FIPPA.
-
Cross-Functional Collaboration: Serve as a trusted advisor to business groups and project teams, assisting in the definition of security requirements, evaluating compliance impacts, and supporting cybersecurity initiatives across enterprise IT and OT landscapes.
Program Enhancement: Assist in supporting broader cybersecurity and compliance programs, reviewing security controls and data sources to continuously improve 's overall security effectiveness and governance capability.
-
Qualifications
-
Minimum five (5) years of working experience in Information Technology.
-
At least three (3) years of focused experience in cybersecurity or equivalent.
-
At least two (2) years of specialized experience in policy development and review.
-
Technical Knowledge & Industry Standards
-
Frameworks & Standards: NIST CSF, NIST 800-53r5, RMF, AI RMF, ISO 27001/2, COBIT, NERC CIP compliance, and BC FIPPA.
-
Environments: Comprehensive understanding of both enterprise IT and Operational Technology (OT) systems.
-
Core Competencies: Cloud security, AI risk governance, security control assessment, vulnerability management principles, and compliance impact analysis.
-
Soft Skills & Competencies
-
Excellent written and spoken communication skills tailored for a professional corporate environment; proven ability to build consensus and act as a trusted advisor to diverse stakeholder groups.
-
: Strong interpersonal skills to work effectively with internal teams, technical leads, and management.
-
Education and Certifications
-
Bachelor’s degree or technical diploma in Computer Science, Information Security, or an equivalent field.
-
Ability to obtain and maintain a security clearance for a Security Sensitive Position classification.
-
Professional Certifications (Assets / Nice-to-Haves)
-
Certified Information Systems Security Professional (CISSP)
-
Certified Information Security Manager (CISM)
-
Certified Information Systems Auditor (CISA)
-
Certified Cloud Security Professional (CCSP)
-
Certified in Risk Information Systems Control (CRISC) / GIAC certifications (GCIH, GPEN).
Additional Information
- Every contractor must supply their own Windows 11 Laptop computer for the duration of the assignment.
-
Every contractor must supply their own “Smart Phone”. This is needed to gain access to the Organizations network.
Looking for meaningful work? We can help!
Raise is an established hiring firm with over 65 years of experience. We believe strongly in making the world a better place through work, which is why we’re a certified B Corporation and donate 10% of our profits to charity.
We strive to build teams that reflect the diversity of the communities we work in. We encourage all qualified applicants to apply, including people from traditionally underrepresented groups such as women, visible minorities, Indigenous peoples, people identifying as LGBTQ2SI, veterans, and people with visible/nonvisible disabilities.
We have a dedicated webpage for accommodations where you can learn more about what we offer and request accommodation: https://raise.jobs/accommodations/
In order to submit candidates for roles, our clients will sometimes require personal information to confirm the identity of applicants and their legal status to work. Raise will never ask you for personal or banking information unless you have been selected for a job. If you are ever unsure about the legitimacy of this or any other Raise job posting (or have any other questions), please contact us at +1 800-567-9675 or [email protected].
#WES
#LI-SC1